Articles on: Spots and reception

Draft a GDPR Notice for Visitors

The GDPR notice is the text displayed to your visitors when they check in. It tells them who you are, why you collect their data, how long you keep it, and what their rights are. It is required under Article 13 of the GDPR.


Anghello provides a compliant notice by default, tailored to the standard purposes of a visitor log (access control, reception, safety, traceability) and based on legitimate interest (Article 6.1.f of the GDPR). This page gives you guidance to assess whether the default template matches your situation. The decision to use the template as is or to customize it is yours.




Your responsibility, our role


By using Anghello, you are the data controller for visit data within the meaning of the GDPR. You are the one who decides why you collect this data and how you use it.


Anghello is your processor (Article 28 of the GDPR): we process the data on your behalf, according to your instructions, within the framework defined by our contract.


The compliance of the notice displayed to your visitors is your responsibility. We provide you with a preconfigured template and customization tools; it is up to you to make sure the published version accurately reflects your practices.


The two available modes


In the Admin app, in the GDPR Notice section, you choose between two modes:




Anghello provides a pre-written notice that covers:


  • the identification of the data controller (your organization)
  • the purposes of processing (access control, host notification, safety of people, access traceability)
  • the legal basis (legitimate interest — Article 6.1.f of the GDPR)
  • the data collected
  • the data recipients
  • the retention periods
  • visitors' rights (access, rectification, erasure, etc.)
  • the ability to lodge a complaint with the CNIL (the French data protection authority)


You fill in a few configuration variables (your organization's name, address, GDPR contact email, retention periods, DPO if applicable) and the notice is generated automatically.


Use this mode if you only collect the standard data of a visitor log and your purposes match those provided by default.


Custom notice


You write the notice yourself in our editor. You can start from the default template and adapt it, or rewrite it entirely.


Use this mode if:


  • you use the visitor's email or phone number for commercial purposes (newsletter, event invitation, prospecting): the legal basis then becomes consent, which must be specifically framed
  • you collect information specific to your industry (certification or insurance number for construction contractors, professional ID card, specific data on high-risk sites)
  • you integrate your visitor log with an internal HR or ERP system
  • your organization has a legal department that wants to apply its own drafting guidelines (vocabulary, structure, additional statements)
  • you are subject to specific sector obligations (public sector, healthcare, defense)


In custom mode, you are solely responsible for the content of your notice. It must meet the requirements of Article 13 of the GDPR - see the next section.


What a GDPR notice must contain


Whichever version you use, the notice must state at least:


  • the identity and contact details of the data controller — that is, your organization
  • the purposes of processing — why you collect the data
  • the legal basis — for a visitor log, this is almost always legitimate interest (Article 6.1.f of the GDPR)
  • the data recipients — who has access to it (your staff, your processors, the authorities upon legal request)
  • the retention period
  • visitors' rights and how to exercise them
  • the ability to lodge a complaint with the CNIL
  • the DPO's contact details, if one has been appointed
  • transfers outside the EU, if applicable


If you write your notice in custom mode, check that each of these points is covered.


Dynamic fields


In the custom notice editor, you can insert dynamic fields that pull the values configured in your Admin app. They guarantee that your notice stays consistent with your configuration: if you change an address or a period, the notice updates automatically.




Field

Content

Organization name

Your company name

Organization address

Your headquarters address

GDPR contact email

The email used for exercising rights (access, rectification, etc.)

Site name

The name of the site or location concerned

Retention period

The total data retention period

Anonymization delay

The delay after which identifying data (first name, last name) is anonymized

DPO name

The name or company name of your Data Protection Officer

DPO email

Your DPO's email

Last updated date

Automatically updated each time the notice is modified


Adapt the notice to your custom fields


If you have enabled custom fields in the check-in form, check that your notice mentions them and states the purposes they relate to.


Fields covered by the default template


The default template already covers several common cases through its generic wording "additional information requested during registration":


  • license plate, purpose of visit — tied to the access control purpose
  • means of transport, mileage — tied to the optional environmental-efforts purpose
  • email, phone number — tied to the purpose of organizing the reception and communicating around the visit (pre-registration confirmation, contact if the host is running late, safety or health alert during or after the visit)


For these fields, you can stay in default mode.


Fields that require switching to custom mode


Some fields introduce a new purpose that the template does not cover. In that case, switch to custom mode and add the corresponding purpose.


A concrete example: collecting email addresses for commercial purposes.


You want to use the visitor's email to send them a newsletter, an event invitation, or to contact them again as part of a commercial prospecting effort. This use goes beyond the "communication around the visit" scope provided by default: it introduces a commercial relationship purpose, which must be declared separately.


Your custom notice should then:


  • add to "Purposes": "where applicable, sending commercial communications or newsletters, subject to the visitor's consent"
  • adapt the legal basis for this purpose: consent (Article 6.1.a of the GDPR) is required — legitimate interest is not sufficient for direct marketing
  • provide a consent collection mechanism separate from the check-in flow (an unticked checkbox, with the option to refuse without blocking access)
  • specify the retention period dedicated to this use and how consent can be withdrawn


Without these adjustments, your notice no longer accurately reflects your processing — which is a breach of Article 13 of the GDPR.


Other cases that require switching to custom mode:


  • collecting a certification number or professional ID card for contractors (construction, industry)
  • integration with an internal HR or ERP system for visitor tracking
  • processing specific to the public sector or healthcare


Appointing a Data Protection Officer (DPO)


Appointing a DPO is only mandatory in certain cases (Article 37 of the GDPR). Most small and mid-sized companies are not concerned. If you have not appointed a DPO, leave the DPO name and DPO email fields empty. The corresponding statement will not appear in your notice.


If you have appointed a DPO (whether internal or outsourced, for example a GDPR consulting firm), fill in their contact details: they will automatically appear in the notice in accordance with Article 13.1.b of the GDPR.


To go further: Do I need to appoint a DPO? (CNIL).


Retention and anonymization periods


Two periods are configured independently.


Retention period


The total time a visitor's data is kept, starting from the day of their visit. Beyond it, all visit data is permanently deleted.


Anghello enforces a maximum period of 12 months, in line with the CNIL's recommendations for access control records. We recommend a default period of 3 months for most use cases.


Anonymization delay (optional)


If you enable it, directly identifying data (first name, last name) is automatically deleted after the chosen delay. The other data (company, timestamps, visit duration) is kept until the total retention period expires.


This option lets you keep visibility over visitor flows (who visits your premises, how often) while minimizing identifying data - a good practice under the data minimization principle (Article 5.1.c of the GDPR).


Anonymized/pseudonymized data is still considered personal data within the meaning of the GDPR. It remains subject to the regulation and will be permanently deleted when the total retention period expires.


The "Platform technical measures" block


This block, positioned at the end of the notice, describes the technical security measures implemented by Anghello: our role as processor, the collection of technical identifiers during QR code check-ins, the 7-day retention period, etc.


It cannot be edited and is automatically added to every notice, whether in default or custom mode.


Why? This block covers our processing (Anghello's, as an independent data controller for platform security), not yours. By keeping it up to date on our side, we guarantee that your visitors are properly informed about every part of the processing, including ours.


For any question about this block, write to us at dpo@anghello.com.


The "Require acknowledgement of the GDPR notice" option




By default, the check-in page displays a statement along the lines of "By registering, you acknowledge having been informed of the processing of your personal data". This is generally legally sufficient.


If you wish, you can enable the Require acknowledgement of the GDPR notice option. Your visitors will then have to check a box confirming they have been informed before they can check in. Anghello also records the date of the notice at the time the box is checked.


Watch the vocabulary: this checkbox is an acknowledgement of information, not consent.


Special cases


Public sector


If you are a public authority or public body, your legal basis for the visitor log may be a task carried out in the public interest (Article 6.1.e of the GDPR) rather than legitimate interest. You are also required to appoint a DPO.


Recommendation: switch to custom mode and adapt the "Legal basis" section accordingly.



If your legal department wants to apply its own drafting guidelines (vocabulary, structure, additional statements), switch to custom mode. The default template is designed as a good starting point to adapt, not as an editorial constraint.


QR code check-in vs kiosk


The notice is the same in both cases. The only difference lies in the collection of technical identifiers (IP address, browser fingerprint) performed by Anghello during QR code check-ins, exclusively for security purposes. This point is covered in the "Platform technical measures" block and requires no action on your part.


Update your notice


Each time you make a change, the last updated date is automatically recalculated and displayed at the bottom of the notice.


We recommend reviewing your notice:


  • whenever your configuration changes (adding fields, changing DPO, modifying periods)
  • whenever your organization changes significantly (change of address or company name)
  • at least once a year, to check that the content is still up to date


Anghello may also update the default template to reflect regulatory changes. If you use default mode, these updates automatically apply to your notice.


FAQ


Is the default notice enough to be GDPR compliant?


Yes, for the standard use case (a classic visitor log). It covers all the statements required by Article 13 of the GDPR. Just make sure your settings (contact details, periods, DPO) are filled in correctly.


Can I go back to default mode after customizing my notice?


Yes, at any time. Your custom changes are kept and can be restored if you want to switch back to custom mode later.


Who is liable in the event of a CNIL inspection?


You are the data controller: you answer for the content of the notice and the overall compliance of your visitors' data processing. Anghello is your processor: we are responsible for the technical security of the platform, the compliance of our own processing (the "Platform technical measures" block), and providing suitable tools.


Can I remove the "Platform technical measures" block?


No. This block describes our processing as an independent data controller, and its presence is necessary for your own compliance: your visitors must be informed of all the processing carried out, including ours.


Can I offer my notice in several languages?


Yes, you can switch to custom mode and add a translated version, keeping the mandatory statements legally accurate.


Useful resources


Updated on: 23/07/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!